PT-2016-1123 · Advantech · Webaccess
Published
2016-01-15
·
Updated
2016-12-03
·
CVE-2016-0857
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Advantech WebAccess versions prior to 8.1
Description
The issue is caused by multiple heap-based buffer overflows, allowing remote attackers to execute arbitrary code via unspecified vectors. This can be exploited by a remote attacker to gain control over the system. The vulnerability is related to the
strcpy function in various services, including datacore.exe and BwpAlarm.dll.Recommendations
For versions prior to 8.1, update to version 8.1 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
datacore.exe and BwpAlarm.dll services until a patch is available.
Avoid using the strcpy function in the affected services until the issue is resolved.Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webaccess